HeaderGuard
Scan a website's HTTP security headers (HSTS, CSP, framing, COOP/CORP, cookies). Score + fixes.
- 0.4.0
- Version
- remote
- Transport
- 1
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 1 tools scanned
- metadata: scanned
No findings.
Tools (1)
scan_headers
Scan the HTTP security headers of a public website. Returns a 0–100 score and A+–F grade (HTTPS 10, HSTS 15, CSP 25, framing 10, X-Content-Type-Options 10, Referrer-Policy 10, Permissions-Policy 5, COOP 5, CORP 5, cookies 5, minus up to 5 for version-leak headers; without HTTPS the score is capped at 39), each header's status and notes, recommended fix headers, and a link to the full report with copy-paste snippets for nginx, Apache, Cloudflare, Netlify, Vercel and Express. Read-only: it sends ordinary GET requests to the site (following up to 10 redirects, each safety-checked) and never reads page bodies. Same engine and scoring as the HeaderGuard JSON API (GET /api/scan).